News & Commentary

Content tagged with Identity & Access Management posted in January 2017
The Trouble With DMARC: 4 Serious Stumbling Blocks
Commentary  |  1/24/2017  | 
Popularity for the Domain-based Message Authentication, Reporting and Conformance email authentication standard is growing. So why are enterprises still struggling to implement it?
Cyber Lessons From NSAs Admiral Michael Rogers
Commentary  |  1/19/2017  | 
Security teams must get better at catching intruders where we have the advantage: on our own networks.
Advances In SSL: 5 Strategies For Secure, High-Performance Load Balancers
Commentary  |  1/17/2017  | 
Today, even Netflix is streaming hit movies and TV shows via encrypted connections! Heres how to manage higher volumes of encrypted traffic without bogging down your network.
10 Cocktail Party Security Tips From The Experts
Slideshows  |  1/13/2017  | 
Security pros offer basic advice to help average users ward off the bad guys.
Credit Freeze: The New Normal In Data Breach Protection?
Commentary  |  1/11/2017  | 
In era of rampant identity theft, consumers should be offered the protection of a credit freeze by default, instead of a nuisance fee each time a freeze is placed or removed.
Survey Points to Slight Rise in Adaptive Authentication Over 2FA
News  |  1/11/2017  | 
SecureAuth study reports a majority of IT decision makers and security pros have issues with two-factor authentication.
A Vendor's Security Reality: Comply Or Good-Bye
Commentary  |  1/4/2017  | 
Privacy compliance is now mission critical. Third-party suppliers that fail to meet data protection mandates will be excluded from doing business in lucrative vertical markets.
Yahoo Customer Database Unaffected By Breaches
Quick Hits  |  1/3/2017  | 
Verto Analytics study reveals longtime users prefer sticking to Yahoo despite hacks to avoid switching hassles.


Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20173
PUBLISHED: 2018-12-17
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVE-2017-18352
PUBLISHED: 2018-12-17
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVE-2017-18353
PUBLISHED: 2018-12-17
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
CVE-2017-18354
PUBLISHED: 2018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
CVE-2017-18355
PUBLISHED: 2018-12-17
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.